Chrome Web Store Verified

uBlock Origin Scope

by [email protected] · 70.0K users · 4.1 rating
83dd025d-fe96-5eb9-9e71-8735fefe5717 | v1.5.1
44/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
Today
Version
v1.5.1
Artifact
SHA256 DAD…888
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

62
Noisy-finding weight
x1.00
Publisher domain
raymondhill.net
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

12 evidence rows available.

Finding Categories

2
Network

Requested Permissions

9 permissions
https://*/*
Dangerous
http://*/*
Dangerous
wss://*/*
Dangerous
ws://*/*
Dangerous
webRequest

Intercept, modify, and block all network requests

High
activeTab
Medium
scripting
Low
storage
Low
webNavigation
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension is published by "[email protected]" — the actual developer email for Raymond Hill, creator of the legitimate uBlock Origin ad blocker. Despite the high finding count (32 high-severity items), all "malware-signature" findings are postinstall_* YARA rules (postinstall_file_manipulation, postinstall_obfuscation, postinstall_network_communication, postinstall_file_download, postinstall_crypto_operations) on "unknown_file". Per documented CVEQ false-positive patterns, these postinstall_* rules match basic Node.js patterns like fetch, exec, fs, and crypto operations, and are classified as code-smell rather than actual malware signatures.

The two network findings are benign: js/lib/publicsuffixlist.js:567 contains a fetch call to the publicsuffixlist library (a legitimate utility for domain parsing), and js/background.js:86 contains a standard fetch operation in the background script. Neither finding references suspicious domains — both are generic fetch calls without malicious destinations.

The threat_indicators metadata confirms zero actual malware signatures, zero obfuscation findings, and zero suspicious IoCs. The 32 high-severity items are all code-smell findings masquerading as malware-signature due to CVEQ's scoring system, which is a known issue that disproportionately inflates risk scores.

A skeptic might argue that the extension name "uBlock Origin Scope" differs from the official "uBlock Origin" and could indicate typosquatting. However, the developer attribution to Raymond Hill's verified email address strongly indicates this is either an official variant or a legitimate related project from the same developer. The description "A tool which reports remote server connections" suggests a diagnostic utility rather than ad-blocking, which is consistent with a scope-testing tool from the uBlock Origin ecosystem. Without evidence of credential theft, data exfiltration to suspicious domains, or actual malware signatures, the findings represent false positives from known CVEQ noise patterns.

Key Reasons

  • Developer email [email protected] belongs to Raymond Hill, creator of legitimate uBlock Origin
  • All malware-signature findings are postinstall_* YARA rules on unknown_file, known false-positive patterns
  • Network findings are generic fetch calls in legitimate files without suspicious domains
  • Threat indicators show zero actual malware signatures, zero obfuscation, zero suspicious IoCs

False Positive Considerations

  • postinstall_* YARA rules matching Node.js patterns
  • Generic fetch calls flagged as network findings
  • Unknown_file paths for code-smell matches
  • Score inflation from code-smell categorized as high-severity

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.

About This Extension

A simple extension which primary purpose is to reveal all the connections -- attempted or successful -- to remote servers. Important: The badge count on the toolbar icon reports the number of distinct third-party remote servers for which there was a connection. Therefore a lower count is more desireable than a higher one. Keep in mind that not all third party remote servers are necessarily to be avoided, though the number of legitimate third parties are usually low count, typically CDNs. The extension uses webRequest listeners to report what exactly happened to network requests made by webpages. This extension is able to report the outcome of network requests regardless of which content blocker is in effect, including content blocking through DNS servers, as long as the browser reports network requests through its webRequest API. Network requests made outside the reach of the webRequest API cannot be reported by this extension.

Frequently Asked Questions